Medium
CVSS 5.0
Overview
upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by...
upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: